Эх сурвалжийг харах

libceph: fix crypto key null deref, memory leak

Avoid crashing if the crypto key payload was NULL, as when it was not correctly
allocated and initialized.  Also, avoid leaking it.

Signed-off-by: Sylvain Munaut <tnt@246tNt.com>
Signed-off-by: Sage Weil <sage@inktank.com>
Reviewed-by: Alex Elder <elder@inktank.com>
Sylvain Munaut 13 жил өмнө
parent
commit
f0666b1ac8

+ 1 - 0
net/ceph/crypto.c

@@ -466,6 +466,7 @@ void ceph_key_destroy(struct key *key) {
 	struct ceph_crypto_key *ckey = key->payload.data;
 	struct ceph_crypto_key *ckey = key->payload.data;
 
 
 	ceph_crypto_key_destroy(ckey);
 	ceph_crypto_key_destroy(ckey);
+	kfree(ckey);
 }
 }
 
 
 struct key_type key_type_ceph = {
 struct key_type key_type_ceph = {

+ 2 - 1
net/ceph/crypto.h

@@ -16,7 +16,8 @@ struct ceph_crypto_key {
 
 
 static inline void ceph_crypto_key_destroy(struct ceph_crypto_key *key)
 static inline void ceph_crypto_key_destroy(struct ceph_crypto_key *key)
 {
 {
-	kfree(key->key);
+	if (key)
+		kfree(key->key);
 }
 }
 
 
 extern int ceph_crypto_key_clone(struct ceph_crypto_key *dst,
 extern int ceph_crypto_key_clone(struct ceph_crypto_key *dst,